Microsoft Secure Score, explained

Secure Score is Microsoft's own measure of how many of its recommended security settings you've turned on. It's useful, but it's easy to misread.

Updated October 4, 2026

What it measures

Secure Score adds up points for recommendations across identity, devices, apps and data, mostly settings in Entra, Defender, Exchange and Intune. Many recommendations depend on licenses, so two companies with the same protection can have very different scores depending on what they pay for.

What it misses

  • Weighting by real-world risk: a missing MFA requirement and a cosmetic setting can count similarly
  • Your domains: SPF, DKIM and DMARC aren't scored the way receivers judge them
  • Signs of an active compromise, like a forwarding rule added yesterday
  • Whether a recommendation is worth the disruption for a company your size

Where to start

  1. 1

    Require MFA for everyone

    Security defaults or Conditional Access. This is the single biggest risk reduction.

  2. 2

    Block legacy authentication

    So old protocols can't sidestep MFA.

  3. 3

    Limit Global Administrators

    Two to four, using separate admin accounts.

  4. 4

    Stop users approving risky apps

    Restrict user consent to verified, low-risk apps.

  5. 5

    Turn on mailbox auditing and external forwarding blocks

    So you can investigate, and attackers can't quietly copy mail out.

Doing it with TenantWard

TenantWard shows your Secure Score alongside its own checks, ranks issues by business impact, and makes the most important changes with a plan, a backup and an undo, including report-only Conditional Access policies you switch on when you're ready.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.